Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformMedium

A security operations center (SOC) analyst is investigating a critical security alert generated by Prisma Cloud related to an S3 bucket with public write access. The analyst needs to quickly understand who made the configuration change that led to this vulnerability. Which Prisma Cloud feature should the analyst utilize to trace the specific user action?

  1. AAsset Inventory
  2. BPolicy Violations Report
  3. CAudit Logs
  4. DAlerts Dashboard
Show answer & explanation

Correct answer: C. Audit Logs

Audit Logs in Prisma Cloud provide a detailed record of all administrative actions performed within the Prisma Cloud console, including who made changes, what changes were made, and when they occurred, making them ideal for tracing user actions.

Why the other options are wrong

  • A. Asset Inventory provides details about cloud resources but does not log administrative actions.
  • B. The Policy Violations Report shows what is currently misconfigured, not who made the change.
  • D. The Alerts Dashboard displays active security alerts but does not provide granular details about the user who initiated the underlying misconfiguration.

Prisma Cloud Audit Logs

A comprehensive record of all administrative and system activities within the Prisma Cloud platform, used for accountability, compliance, and forensic analysis.

  • Tracks user logins, policy changes, alert dismissals.
  • Includes timestamps, user IDs, and action details.
  • Essential for security investigations and compliance audits.

Memory trick: To find out 'who did what,' look for the logs of their actions.

More Prisma Cloud Platform questions